You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在SEPolicy中添加新服务遇libsepol.check_assertions断言失败求助

解决SEPolicy添加自定义服务时的neverallow断言失败问题

我之前也碰到过完全一样的问题,咱们先把问题根源理清楚,再一步步解决:

问题重现

你在添加自定义verifyusb.sh服务的过程中,先是遇到了verifyusb_exec需要关联system_file_type的错误,添加该属性后又触发了SEPolicy的neverallow断言失败,核心错误提示如下:

libsepol.report_failure: neverallow on line 1029 of system/sepolicy/public/domain.te (or line 14463 of policy.conf) violated by allow verifyusb verifyusb_exec:file { read getattr map execute entrypoint open };

问题根源

这个neverallow是SEPolicy的核心安全限制:自定义domain(你创建的verifyusb)不允许执行带有system_file_type属性的可执行文件。system_file_type是为系统核心二进制文件(比如/system/bin下的原生系统工具)设计的属性,自定义脚本放在/system/bin并添加该属性,直接触碰了安全检查规则。

解决方案(优先推荐方案1)

方案1:将脚本移至/vendor/bin或/product/bin目录

这是最合规的处理方式,/vendor和/product分区是厂商自定义内容的专属分区,不需要system_file_type属性,能完美避开neverallow限制:

  1. 修改脚本拷贝路径
    调整构建文件(比如Android.mk)中的拷贝规则:

    LOCAL_DEVICE_MEDIA := device/xxx/XXX/verifyusb.sh:vendor/bin/verifyusb.sh
    

    如果是用product分区,就改成product/bin/verifyusb.sh

  2. 更新init.rc中的启动路径
    修改init.rc里的执行命令,对应新的脚本路径:

    on boot
           exec - root root system readproc -- /vendor/bin/verifyusb.sh
  3. 修正file_contexts配置
    在device/xxx/xxx/sepolicy/xxx/file_contexts中更新路径匹配规则:

    /vendor/bin/verifyusb.sh u:object_r:verifyusb_exec:s0
    
  4. 恢复verifyusb.te的定义
    去掉之前添加的system_file_type属性,回到初始的合规定义:

    type verifyusb, domain;
    type verifyusb_exec, exec_type, file_type;
    init_daemon_domain(verifyusb)
    

方案2:若必须放在/system/bin下(不推荐)

如果因为特殊需求必须保留在/system/bin,可以添加neverallow的例外规则,但这会降低系统安全性,仅作为临时应急方案:
在verifyusb.te中添加例外声明:

type verifyusb, domain;
type verifyusb_exec, system_file_type, exec_type, file_type;
init_daemon_domain(verifyusb)

# 添加例外,绕过domain.te中的neverallow限制
neverallow_exceptions verifyusb verifyusb_exec:file { execute entrypoint read getattr map open };

验证步骤

修改完所有配置后,清理旧编译产物再重新编译:

make clean && make -j$(nproc)

内容的提问来源于stack exchange,提问作者GNK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 10:27:28